Lucene search

K
cveMitreCVE-2008-3626
HistorySep 11, 2008 - 1:13 a.m.

CVE-2008-3626

2008-09-1101:13:09
CWE-119
mitre
web.nvd.nist.gov
32
cve-2008-3626
apple quicktime
memory corruption
application crash
remote attackers

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.034

Percentile

91.6%

The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

Affected configurations

Nvd
Node
applequicktimeRange≀7.4.5
OR
applequicktimeMatch-
OR
applequicktimeMatch3.0
OR
applequicktimeMatch4.1.2
OR
applequicktimeMatch5.0
OR
applequicktimeMatch5.0.1
OR
applequicktimeMatch5.0.2
OR
applequicktimeMatch6.0
OR
applequicktimeMatch6.5
OR
applequicktimeMatch6.5.1
OR
applequicktimeMatch6.5.2
OR
applequicktimeMatch7.0
OR
applequicktimeMatch7.0.1
OR
applequicktimeMatch7.0.2
OR
applequicktimeMatch7.0.3
OR
applequicktimeMatch7.0.4
OR
applequicktimeMatch7.1
OR
applequicktimeMatch7.1.1
OR
applequicktimeMatch7.1.2
OR
applequicktimeMatch7.1.3
OR
applequicktimeMatch7.1.4
OR
applequicktimeMatch7.1.5
OR
applequicktimeMatch7.1.6
OR
applequicktimeMatch7.2
OR
applequicktimeMatch7.3
OR
applequicktimeMatch7.3.1
OR
applequicktimeMatch7.3.1.70
OR
applequicktimeMatch7.4
OR
applequicktimeMatch7.4.4
VendorProductVersionCPE
applequicktime*cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
applequicktime-cpe:2.3:a:apple:quicktime:-:*:*:*:*:*:*:*
applequicktime3.0cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*
applequicktime4.1.2cpe:2.3:a:apple:quicktime:4.1.2:*:*:*:*:*:*:*
applequicktime5.0cpe:2.3:a:apple:quicktime:5.0:*:*:*:*:*:*:*
applequicktime5.0.1cpe:2.3:a:apple:quicktime:5.0.1:*:*:*:*:*:*:*
applequicktime5.0.2cpe:2.3:a:apple:quicktime:5.0.2:*:*:*:*:*:*:*
applequicktime6.0cpe:2.3:a:apple:quicktime:6.0:*:*:*:*:*:*:*
applequicktime6.5cpe:2.3:a:apple:quicktime:6.5:*:*:*:*:*:*:*
applequicktime6.5.1cpe:2.3:a:apple:quicktime:6.5.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 291

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.034

Percentile

91.6%